Cross-Site Scripting Vulnerability in Empathy by GNOME
CVE-2011-4170
Currently unrated
What is CVE-2011-4170?
The vulnerability exists in the theme_adium_append_message function of the Adium theme within libempathy-gtk in Empathy versions 3.2.1 and earlier. It enables remote attackers to exploit crafted aliases (nicknames) in /me events, thereby injecting malicious web scripts or HTML content. Successful exploitation can lead to unauthorized actions performed on behalf of users, causing potential data breaches and disruption.